# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=37

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 38

---

## [Filebeat sends 20 days old logs](https://discuss.elastic.co/t/filebeat-sends-20-days-old-logs/344049)

<div class="topic-metadata">

**Author:** [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 9:06am UTC](https://discuss.elastic.co/t/filebeat-sends-20-days-old-logs/344049 "2023-09-28T09:06:58Z")

</div>

Hello, I had approximately 12 hours of downtime on one server (RHEL8) but after it was online again, filebeat started to send logs from the time of downtime. Now, I can see logs in Kibana that have timestamp of the day …

---

## [Kuberentes metadata are missing on the pod logs](https://discuss.elastic.co/t/kuberentes-metadata-are-missing-on-the-pod-logs/344035)

<div class="topic-metadata">

**Author:** [@Raoudha\_Lagha](https://discuss.elastic.co/u/Raoudha_Lagha)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 6:54am UTC](https://discuss.elastic.co/t/kuberentes-metadata-are-missing-on-the-pod-logs/344035 "2023-09-28T06:54:43Z")

</div>

Hello Could you please help us with this issue: we found out that some of our pod logs are missing Kubernetes metadata. We are running on Kubernetes version 1.24 and using Karpetener to provision the nodes, The Filebe…

---

## [MetricBeats to Scrap Metrics From Confluent For Kubernetes ( CFK ) PODS](https://discuss.elastic.co/t/metricbeats-to-scrap-metrics-from-confluent-for-kubernetes-cfk-pods/344021)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 3:28am UTC](https://discuss.elastic.co/t/metricbeats-to-scrap-metrics-from-confluent-for-kubernetes-cfk-pods/344021 "2023-09-28T03:28:37Z")

</div>

Hi All , We have central elastic and have Confluent Kafka deployed onto OpenShift cluster ( CFK). Understand from Confluent Docs that , all CFK pods are exposing metrics with promethus exporter. So I am planning to use…

---

## [What is the default source of the @timestamp field in Filebeat?](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 8:59pm UTC](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640 "2023-09-27T20:59:01Z")

</div>

I'm ingesting Syslog input with Filebeat, and I'd like to use the timestamp processor to adjust the timezone of the logs (my source is sending them in local time and Kibana is expecting UTC). According to the documentati…

---

## [Multiple input log, reading the same files](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:45pm UTC](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013 "2023-09-27T20:45:17Z")

</div>

Hi, it is posible to use multiple inputs on the same files, but with different filters? The configuration below works but only if I run filebeat with: ./filebeat.exe -c filebeat.yml not when I run it as a service UPDA…

---

## [Filebeat modules vs filestream input](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 29\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/filebeat-modules-vs-filestream-input/342871 "2023-09-27T18:45:19Z")

</div>

Hello, I'm trying to configure filebeat to read a Linux system and auth log file. when I'm using datastream input, the data isn't parsed well; everything is let into the message field without any processing. When I use…

---

## [Heartbeat configuration for 1000+ IPs](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [September 27, 2023, 6:41pm UTC](https://discuss.elastic.co/t/heartbeat-configuration-for-1000-ips/342803 "2023-09-27T18:41:03Z")

</div>

Hi gurus, We have a requirement to monitor1000+ IPs using Heartbeat 7.17.4. As the baseline test, we pinged one IP address (let's call it device A) with cmd ping and the latency is around 30ms. Then we started adding …

---

## [Filebeat 8.7.1 utilizing too much of Memory and pods get OOM Killed](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-8-7-1-utilizing-too-much-of-memory-and-pods-get-oom-killed/344004 "2023-09-27T16:12:19Z")

</div>

We are seeing filebeat pods using a lot of memory and restarting at random intervals due to OOM. Any solution for this? Even in a 3 node kubernetes cluster with very little resources running seeing the issue.

---

## [Filebeat Cisco Modules for Nexus](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914)

<div class="topic-metadata">

**Author:** [@acardona](https://discuss.elastic.co/u/acardona)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:11pm UTC](https://discuss.elastic.co/t/filebeat-cisco-modules-for-nexus/343914 "2023-09-26T17:11:12Z")

</div>

Hi, I am trying to set up syslogging from a nexus switch to feed into Filebeat's Cisco module that would then feed into Elasticsearch. I tend to get the same error message after enabling the cisco module and running thi…

---

## [How to add persistent data to filebeat](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 2:55pm UTC](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981 "2023-09-26T14:55:15Z")

</div>

I have some log files that only in the first line it will display the version of the file, but I want to use that version everywhere in the log. is there a way I can store that data and use it for the rest of the file? …

---

## [Packetbeat MongoDB in Windows Server doesn't work](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:53pm UTC](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903 "2023-09-26T14:53:30Z")

</div>

Hi I'm trying to monitor mongodb connections using packetbeat, doing it locally on my mongodb works fine: this is my configuration: packetbeat.interfaces: - device: \\Device\\NPF\_{422A5385-8A2F-46AB-8B71-2C94764B14FA} …

---

## [Unable to send metricbeat to aws MSK kafka with sasl\_ssl authentication](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885)

<div class="topic-metadata">

**Author:** [@Kotesh\_Nataru](https://discuss.elastic.co/u/Kotesh_Nataru)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885 "2023-09-26T13:25:26Z")

</div>

I have created AWS MSK service with SASL\_SSL authentication and able to send/receive data through python code to it. i am trying to send metricbeat and getting the below error. this if from windows machine Here is the m…

---

## [Installation and configuring metricbeat in docker](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736)

<div class="topic-metadata">

**Author:** [@swikriti.debnath](https://discuss.elastic.co/u/swikriti.debnath)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:29pm UTC](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736 "2023-09-26T12:29:42Z")

</div>

Already seen metric beat installation detailed video but without docker . Please arrange one detailed series on metric beat docker installation and configuration.

---

## [Heartbeat Http & ICMP - Discovery from CMDB](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 6:31am UTC](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835 "2023-09-26T06:31:28Z")

</div>

Hello, We would like to build the config file ex: heartbeat.yml from our CMDB (ServiceNow & Netbox) inventory. Is it something possible ? Thanks, Praveen

---

## [Data collection and labeling with some of the Beats](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 5:20am UTC](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824 "2023-09-26T05:20:17Z")

</div>

Hello everyone, I am currently engaged in an exploration of Elastic Stack's Beats products, specifically Packetbeats, FileBeats, WinlogBeats, and Metricbeats, across Linux and Windows platforms. My end goal is to levera…

---

## [Winlogbeat stopping due to Exception](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819)

<div class="topic-metadata">

**Author:** [@risshukla](https://discuss.elastic.co/u/risshukla)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:22am UTC](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819 "2023-09-26T01:22:35Z")

</div>

We've been using Winlogbeat to forward Workstation logs to Logstash. However, we've encountered an issue after installing Winlogbeat (versions 8.10.2) on our Windows Server 2022. The issue is as follows: Exception 0xc0…

---

## [Filebeat-7.17.12-system-syslog-pi peline\] does not exist](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735)

<div class="topic-metadata">

**Author:** [@YassBout](https://discuss.elastic.co/u/YassBout)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:46am UTC](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735 "2023-09-25T09:46:18Z")

</div>

Hello, I've installed the ELK stack on a VPS to monitor remote logs from multiple companies. However, when I install and start all the services, I encounter this error: 2023-08-27T09:17:59.426Z#011INFO#011\[publisher\]#0…

---

## [Heartbeat http.yml config sends data of one service in index and if same service running on diffrent server dont send datah](https://discuss.elastic.co/t/heartbeat-http-yml-config-sends-data-of-one-service-in-index-and-if-same-service-running-on-diffrent-server-dont-send-datah/343600)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 8:03am UTC](https://discuss.elastic.co/t/heartbeat-http-yml-config-sends-data-of-one-service-in-index-and-if-same-service-running-on-diffrent-server-dont-send-datah/343600 "2023-09-22T08:03:31Z")

</div>

Hello All, I have configured services under monitor.d using http.yml.(8.8.2 verion beats) I want to monitor multiple services in various host. Current issue is I'm monitoring same service hosted in two diffrenent serv…

---

## [\[elastic-agent\] \<defunct\> Version 8.9.1](https://discuss.elastic.co/t/elastic-agent-defunct-version-8-9-1/343588)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 2:54am UTC](https://discuss.elastic.co/t/elastic-agent-defunct-version-8-9-1/343588 "2023-09-22T02:54:06Z")

</div>

I am aware of few related issue for elastic-agent going into defunct , they appear to be for older version and a fix was applied for 8.5 We are on version 8.9.1 and still seeing this on Centos 7.x , please advice if …

---

## [Filebeat is not sending a continuous stream to Logstash](https://discuss.elastic.co/t/filebeat-is-not-sending-a-continuous-stream-to-logstash/342862)

<div class="topic-metadata">

**Author:** [@surfingjoe](https://discuss.elastic.co/u/surfingjoe)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 10:06pm UTC](https://discuss.elastic.co/t/filebeat-is-not-sending-a-continuous-stream-to-logstash/342862 "2023-09-21T22:06:54Z")

</div>

I'm running a development set of servers (not production). I have an ELK server, a web server, and a reverse proxy server. Data from the web server and the reverse proxy have successfully been sent into Logstash on the E…

---

## [Lost aws module (rds metricset) metrics after upgrade from 7.17 -\> 8.8.2](https://discuss.elastic.co/t/lost-aws-module-rds-metricset-metrics-after-upgrade-from-7-17-8-8-2/343388)

<div class="topic-metadata">

**Author:** [@m\_standfuss](https://discuss.elastic.co/u/m_standfuss)\
**Replies:** 3\
**Last updated:** [September 21, 2023, 5:51pm UTC](https://discuss.elastic.co/t/lost-aws-module-rds-metricset-metrics-after-upgrade-from-7-17-8-8-2/343388 "2023-09-21T17:51:13Z")

</div>

After upgrading from 7.17 to 8.8.2 we are no longer getting any of our rds metrics from the aws module. We are running on EKS in AWS, nothing changed in terms of the modules configured, overall metricbeats configuration…

---

## [Winlogbeat range doesnt seem to work for drop\_events filter](https://discuss.elastic.co/t/winlogbeat-range-doesnt-seem-to-work-for-drop-events-filter/343556)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 2:41pm UTC](https://discuss.elastic.co/t/winlogbeat-range-doesnt-seem-to-work-for-drop-events-filter/343556 "2023-09-21T14:41:43Z")

</div>

Using version 8.9.1 The range in drop events doesn't seem to work: range.winlog.event\_id: { gte: 1100, lte: 4609 } Its throws a waning and also doesnt send the data. Thanks, JJ

---

## [Measure CPU/Memory for custom libbeat application](https://discuss.elastic.co/t/measure-cpu-memory-for-custom-libbeat-application/343538)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 12:23pm UTC](https://discuss.elastic.co/t/measure-cpu-memory-for-custom-libbeat-application/343538 "2023-09-21T12:23:02Z")

</div>

I have built a custom beat using libbeat library that parses my application logs as intended. Is there an out of the box configuration that can be added in yml file to log cpu and memory stats for this beat. I can use Me…

---

## [No event.category in Winlogbeat](https://discuss.elastic.co/t/no-event-category-in-winlogbeat/343346)

<div class="topic-metadata">

**Author:** [@Ronger03](https://discuss.elastic.co/u/Ronger03)\
**Replies:** 6\
**Last updated:** [September 21, 2023, 8:33am UTC](https://discuss.elastic.co/t/no-event-category-in-winlogbeat/343346 "2023-09-21T08:33:15Z")

</div>

Hello, I configured winlogbeat to send windows events to Logstash but I see no event.category field in the events received on Logstash. Then I tried to debug by disable Logstash output, enable file output and still see…

---

## [Winlog beat connection issues](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 3:44am UTC](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286 "2023-09-21T03:44:39Z")

</div>

Hi, We are seeing a large number of connections from winlogbeat to EH Kafka. We have increased the keep alive setting as per the kafka recommendation by MS to 180,000 and also changing the partition setting to random. I…

---

## [Filebeat Kafka input compatibility](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500)

<div class="topic-metadata">

**Author:** [@niaomingjian](https://discuss.elastic.co/u/niaomingjian)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 3:36am UTC](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500 "2023-09-21T03:36:29Z")

</div>

The doc says: This input works with all Kafka versions in between 0.11 and 2.8.0. Older versions might work as well, but are not supported. My kafka Cluster version is 3.3. Does kafka input of filebeat support kafk…

---

## [FileBeat on OpenShift Cluster (RHOCS ) - Operation not permitted error](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 2:16am UTC](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421 "2023-09-21T02:16:09Z")

</div>

Hi All , I have used FIleBeat docker image and created a daemon set on our Openshift cluster and gave necessary permissions to run as a privileged container as per documentation. Here is my volume and volume mount sect…

---

## [Can't get Filebeat to ship Nginx Ingress Controller logs using ECK](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472)

<div class="topic-metadata">

**Author:** [@krische](https://discuss.elastic.co/u/krische)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 7:54pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472 "2023-09-20T19:54:06Z")

</div>

I have ECK setup and running on my kubernetes cluster. I followed the Configuration Examples to setup filebeat ship all container logs to Elasticsearch. That is working fine. However, now I am trying to parse the logs o…

---

## [Documentation on the relationship between output fields and input plugins/processors](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 1:53pm UTC](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467 "2023-09-20T13:53:16Z")

</div>

Various pages on the Filebeat documentation describe inputs: Configure inputs | Filebeat Reference \[8.10\] | Elastic . Similarly, processors are documented: Filter and enhance data with processors | Filebeat Reference \[8.…

---

## [Metricbeat 7.13 not working](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439)

<div class="topic-metadata">

**Author:** [@Spottie](https://discuss.elastic.co/u/Spottie)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:56am UTC](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439 "2023-09-20T09:56:10Z")

</div>

I have a docker setup with multiple containers running and then setup a filebeat that logs into my elasticsearch. Now I wanted to setup a metricbeat as described here: Set up and run Metricbeat | Metricbeat Reference \[7…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=36)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=38)
